CVE-2022-25647
01.05.2022, 16:15
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.Enginsight
Vendor | Product | Version |
---|---|---|
gson | 2.2.3 ≤ 𝑥 < 2.8.9 | |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
netapp | active_iq_unified_manager | - |
oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.2.0 |
oracle | financial_services_crime_and_compliance_management_studio | 8.0.8.3.0 |
oracle | graalvm | 20.3.6 |
oracle | graalvm | 21.3.2 |
oracle | graalvm | 22.1.0 |
oracle | retail_order_broker | 18.0 |
oracle | retail_order_broker | 19.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References